KB Article: Generate Client ID, Client Secret & Tenant ID for Microsoft 365 OAuth & Configuring SMTP in BDRShield

KB Article: Generate Client ID, Client Secret & Tenant ID for Microsoft 365 OAuth & Configuring SMTP in BDRShield

Overview

This guide provides step-by-step instructions on how to:
Register an application in Microsoft Azure to generate:
  1. Client ID
  2. Client Secret
  3. Tenant ID
Use these credentials to configure SMTP with OAuth in BDRShield. 

Steps to Generate Client ID, Client Secret, and Tenant ID for M365

Step 1: Log in to portal.azure.com using your work-email account.
Step 2: Navigate to App Registration. You can use the search option to find it quickly. Then click New Registration. (Ensure your Microsoft 365 account can register apps. If App Registration is disabled, ask your admin to enable it).
Step 3: Enter a name of your choice for the Application and choose the supported account types: "Accounts in the organizational directory only."
Step 4: Select Web in the Select a Platform field.
Step 5: Specify the Redirect URL as follows:
Info

a) If your BDRShield Backup Server is self-hosted:

  1. If your BDRShield server is accessed only locally using local IP addresses, Provide a redirect URI in following format: https://<ip_address>.nip.io:<port_number> , Eg: https://192.168.103.8.nip.io:6061
  2. If your BDRShield server is accessed using a public domain name or a public IP addresses, Provide a redirect URI in the following format: https://<public_ip_address or public_domain_name>:<port_number>, Eg: https://bdr.example.com:6061
  3. If your BDRShield server is accessed using the domain name localhost, provide a redirect URI in the following format: https://localhost:<port_number>,  Eg: https://localhost:6061.

b) If you have signedup for BDRShield Cloud Server:

  1. For Microsoft 365 OAuth - configure the following Redirect URI in your OAuth application: https://console1.bdrshield.com/emailoauth/o365
Step 6: Copy the Client ID and Tenant ID displayed and keep them safe for later use.
Step 7: In the left pane, under Manage > click Certificates & secrets > New client secret. 
Step 8: Provide a description for the client secret. In the Expires field, choose the validity of the client secret and add.
Step 9: The client secret will be generated. Copy the string displayed under "Value" and keep it safe for later use.

  Steps to Configure SMTP for Microsoft 365 OAuth:

  1. Open the redirect URL (specified in Step 5 of Generation of App for OAuth) directly in your browser.
  2. Login into the respective BDRShield Backup Server web-console with admin credentials.
  3. Access the SMTP settings page: Inventory -> Configurations -> SMTP.
  4. Provide values in various fields such as SMTP Server etc.. as per Office 365's settings.
  5. For the "Authentication" field, choose Select OAuth > Office 365.
  6. Provide the Client ID, Client Secret, and Tenant ID you saved earlier during the Office 365 Application creation process.
  7. Ensure that all fields are appropriately filled and click "Authorize and Save".
  8. Proceed with the OAuth consent process.
Notes
Note: To complete the consent process, your account needs to have appropriate permissions to the following scopes: SMTP.Send, offline_access, openid, profile, email. If you face any problems, contact your Organization Admin and check the permissions.